CVE-2024-22168

EUVD-2024-19764
A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to carry out malicious activities.The web apps for these devices have been automatically updated to resolve this vulnerability and improve the security of your devices and data.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
western_digitalmy_cloud_home_web_app
𝑥
< 4.28.0-102
ADP
sandiskibi_web_app
𝑥
< 4.28.0-102
ADP
western_digitalwd_cloud_web_app
𝑥
< 4.28.0-102
ADP
western_digitalmy_cloud_web_app
𝑥
< 4.28.0-102
ADP